Review Terraform Security
review_terraform_securityInspect raw Terraform plan JSON to flag destructive actions, public exposure, encryption gaps, deletion protection issues, and IAM wildcard risks without executing Terraform or writing state.
Instructions
Inspect raw Terraform plan JSON for security-relevant changes such as destructive actions, public exposure, encryption gaps, deletion protection and IAM wildcard risk. Use this for Terraform security posture; use assess_terraform_change for broader release/change risk and governance. It parses the supplied plan only and does not execute Terraform or write state.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| environment | No | Optional target environment used to contextualize the severity of findings. | |
| terraformPlanJson | Yes | Raw Terraform plan JSON, typically produced by terraform show -json, to inspect for security-relevant resource changes. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| findings | Yes | ||
| riskLevel | Yes | ||
| riskScore | Yes | ||
| policyPack | Yes | ||
| environment | Yes | ||
| findingCount | Yes | ||
| highFindings | Yes | ||
| replacements | Yes | ||
| mediumFindings | Yes | ||
| recommendedGate | Yes | ||
| changedResources | Yes | ||
| criticalFindings | Yes | ||
| destructiveChanges | Yes | ||
| assessmentConfidence | Yes |